If a CCSSA identifies areas of non-compliance during a CCSS audit, those findings are documented.
In some cases, the entity may be able to provide additional evidence to demonstrate the control has been met, or that compensating controls achieve the same security objective. If the gaps cannot be resolved, remediation may be required before the system can be certified or maintain its certification. The auditor uses professional judgment to evaluate whether implemented controls sufficiently satisfy the intent of the CCSS control.
The goal of the audit is not simply to identify deficiencies, but to provide assurance that the system’s security controls are effective, properly implemented, and operating as intended. If a system does not meet the requirements for the desired certification level, it may still qualify for a lower CCSS level if all requirements for that lower level are satisfied, since the overall certification is determined by the lowest level achieved across all applicable aspects.